AI–ENABLED PREDICTIVE CYBER THREAT INTELLIGENCE FOR IOT NETWORKS: A MULTI-SCALE ATTENTION-ENHANCED CNN FRAMEWORK INTEGRATING BEHAVIORAL ANALYTICS, SPATIOTEMPORAL NETWORK TRAFFIC MODELING, AND ADAPTIVE CYBERATTACK PREDICTION
Keywords:
Internet of Things; Cyber Threat Intelligence; Multi-Scale Attention-Enhanced CNN (MSAE-CNN); Behavioral Analytics; Spatiotemporal Network Traffic Modeling; Cyberattack Prediction; Deep Learning; Intrusion Detection Systems.Abstract
The rapid proliferation of Internet of Things (IoT) devices has fundamentally transformed modern digital ecosystems while simultaneously expanding the cyberattack surface through heterogeneous devices, dynamic communication patterns, resource-constrained endpoints, and continuously evolving security threats. Conventional intrusion detection systems are predominantly reactive and often demonstrate limited effectiveness in identifying sophisticated, previously unseen, and temporally evolving attacks. To address these limitations, this study proposes an AI-enabled predictive cyber threat intelligence framework based on a Multi-Scale Attention-Enhanced Convolutional Neural Network (MSAE-CNN) that integrates behavioral analytics, spatiotemporal network traffic modeling, and adaptive cyberattack prediction for intelligent IoT security. The proposed framework analyzes packet- and flow-level characteristics, device communication behavior, temporal traffic variations, protocol activities, authentication patterns, and statistical network indicators to construct comprehensive representations of legitimate and malicious IoT activities. A systematic preprocessing pipeline incorporating missing-value treatment, categorical encoding, feature normalization, class balancing, and sliding-window temporal segmentation is employed to improve data consistency and model generalization. Multi-scale convolutional layers capture attack signatures at different levels of granularity, while integrated channel and spatial attention mechanisms dynamically prioritize security-sensitive features and suppress redundant traffic information. Spatiotemporal analysis further enables the model to capture evolving dependencies between device behavior and network activity, thereby supporting proactive identification of emerging attacks. The framework was implemented and evaluated in MATLAB using IoT cybersecurity traffic representing normal behavior and multiple attack categories, including DDoS, DoS, reconnaissance, botnet, spoofing, brute-force, and malicious communication attacks. Experimental results demonstrate that the proposed MSAE-CNN achieved 98.72% accuracy, 98.41% precision, 98.56% recall, 98.63% specificity, 98.48% F1-score, and 0.996 ROC-AUC, with a false-positive rate of only 1.37%. In comparison, conventional CNN, LSTM, CNN-LSTM, ResNet-based, and attention-CNN models achieved accuracies of 91.84%, 93.67%, 95.26%, 96.41%, and 97.18%, respectively. Furthermore, the proposed framework reduced average attack-detection latency by 31.6% and improved early threat-prediction capability by 18.9% compared with the strongest benchmark model. The findings demonstrate that the integration of multi-scale feature learning, attention-driven representation, behavioral intelligence, and spatiotemporal traffic modeling provides an accurate, adaptive, and computationally effective approach for proactive cyber threat intelligence and resilient security management in next-generation IoT networks.












